Multi-CloudCIO BriefingsRetrospectives

CIO Brief: Pipeline Supply-Chain Risk Explained

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from March 2025, written in 2026 with the benefit of hindsight.

The short version: In March 2025, a popular add-on used in tens of thousands of software build pipelines was hijacked. It quietly printed companies' secret keys into logs — some publicly visible. Nobody at those companies changed anything; their pipelines simply trusted a tool that changed underneath them.

What a build pipeline supply-chain attack is

Modern software is built by automated pipelines that use many third-party components. If one of those components is compromised, the attacker's code runs inside your build — with access to the keys used to deploy to production.

The business impact

  • Leaked cloud and production credentials.
  • Potential tampering with software you ship.
  • Emergency rotation work across teams.

Questions to ask your team

  • Which third-party components run in our build pipelines?
  • Are they locked to specific, reviewed versions, or do they update automatically?
  • Do our pipelines store long-lived cloud keys?
  • Did the tj-actions incident affect us, and how did we confirm?

What good looks like

Pipeline components locked to reviewed versions, an approved list of allowed components, no long-lived secrets in pipelines, and monitoring for unusual pipeline behavior.

The decision

Ask engineering to lock all third-party pipeline components to fixed versions and remove stored cloud keys from pipelines. Both are well-understood fixes with outsized risk reduction.

tj-actions compromise impacttj-actions supply chain2025

More on this story